Privacy Policy
Last updated: July 24, 2026 | Version 2.0
Translation notice
This document is an informational translation of the original Polish version. If the versions differ, the Polish text governs to the extent permitted by mandatory law, in particular mandatory consumer-protection rules.
1. Data Controller
The data controller for your personal data is the owner of the QrKontakt service, operating as a sole proprietor:
- Company: ADAKS MEDIA DANIEL DOBROWOLSKI
- Tax ID (NIP): PL6152062671
- Registered address: MΕciszΓ³w 112B, 59-800 LubaΕ, Poland
- E-mail: [email protected]
Service available at: qrkontakt.com
2. Data Protection Officer
Due to the scale of processing, the controller is not required to appoint a Data Protection Officer (DPO). For data protection inquiries, contact us directly at: [email protected].
3. Personal Data We Collect
3.1. Registration Data
- Email address
- First name and last name
- Password (stored only as a cryptographic hash β never in plain text)
3.2. OAuth Login Data (Google / Apple)
- Email address verified by the provider
- Name from the provider profile
- Encrypted access token (sodium_crypto_secretbox encryption)
3.3. Contact Form Data
- Sender's name
- Sender's email address
- Phone number (optional)
- Message content
- File attachments uploaded by the sender
3.4. QR Sticker Data
- 20-character sticker code and the technical QR token used in its public URL
- Scan data: timestamp, scan counter and short-lived technical identifiers used for abuse limits and duplicate notification suppression
3.5. Payment Data
- Transaction data (amount, date, status) stored on our side
- Card and bank account data is processed exclusively by Stripe Inc. and PayNow (mBank S.A.) β we do not store it on our servers
3.6. Shipping Address Data
- Recipient's full name
- Delivery address (street, postcode, city, country)
- Contact phone number (for the courier)
3.7. Technical Data
- User sessions (session cookies)
- A random app-installation identifier (UUID) and its pseudonymised HMAC digest, used only for manual security analysis of whether the same installation appeared on multiple accounts; we do not collect hardware identifiers for this purpose or make automated decisions
- Passkey data: public credential identifier and key, AAGUID, transports, counter, synchronization flags and creation/use dates; we never receive the private key or biometric data
- IP hashes for rate limiting β no raw IP addresses
- Error logs (Sentry) β technical error data, pseudonymised identifiers and minimal diagnostic context
- Web push VAPID endpoint; for mobile push: FCM token, Firebase Installation ID where supplied by the SDK, app installation/session identifier, platform, device model/name, OS and app versions, app language and notification-category preferences
- Owner data voluntarily made public for a sticker: sticker name, owner message and up to three labelled phone numbers
- Referral codes: 8-character code linked to the user's account
- Cloudflare Turnstile anti-spam data: verification token, IP address sent to the CAPTCHA provider and verification result
3.8. Browser Fingerprint
To protect the contact form against spam and group correspondence from the same browser, we generate a cryptographic hash on the client side from the following browser signals:
- Canvas rendering hash (rendering engine signature)
- WebGL renderer name
- Navigator data (user agent, platform, language, hardware concurrency)
- Screen resolution and colour depth
- Timezone offset
These signals are combined and immediately hashed β we store only the resulting hash, never the raw data. This hash is used for message rate limiting, spam blocking and assigning subsequent messages from the same browser to one conversation history. It is not used for advertising or marketing analytics.
Legal basis: Art. 6(1)(f) GDPR β legitimate interest of the controller (protecting the service from abuse).
3.9. Location Data (GPS) in Lost Mode
When an Owner activates Lost Mode for a sticker, visitors to the item's public page can voluntarily share their GPS location. Before the browser's location prompt appears, a preliminary consent modal is displayed to ensure informed consent.
- We store latitude, longitude and optional accuracy with a GPS message, show them to the Owner in the app/dashboard and may send a map link by email. They are deleted from the active database no later than 30 days after sharing.
- Protected disaster-recovery backups may temporarily contain the record and are rotated within no more than 30 days; retention rules are reapplied after a restore.
- Sharing location data is entirely voluntary, and the user must actively choose to do so after reviewing the consent modal.
- To prevent abuse, a rate limit applies: a maximum of 3 location shares per IP address per sticker within a 24-hour period.
Legal basis: Art. 6(1)(a) GDPR β explicit consent. The individual sharing their location is the data subject; the sticker Owner receives the data acting as an independent data controller for the sole purpose of recovering the lost item.
3.10. Withdrawal and Return Process Data
When you submit a withdrawal request through the customer dashboard form or by email, we process:
- Order number
- Reason for withdrawal (category + optional text comment, max. 1000 characters)
- Date of request submission
- Return address (if different from the delivery address)
- Return parcel tracking number (optional)
- Administrator decision (acceptance/rejection) and its justification
- Information on any refund reduction (Art. 34(4) of the Polish Consumer Rights Act β Polish law) and its justification
Legal basis: Art. 6(1)(c) GDPR β legal obligation (Polish Consumer Rights Act of 30 May 2014) and Art. 6(1)(b) GDPR β performance of a contract.
Retention period: 6 years from the end of the calendar year in which the credit note was issued (Polish tax law: Art. 86 Β§ 1 Ordynacja podatkowa and Art. 74 Accounting Act β tax and accounting requirements).
Recipients: data may be shared with payment operator PayNow (mBank S.A.) to the extent necessary to process the refund. Withdrawal form data is not shared with third parties for other purposes.
3.11. Reports of Public Sticker Content
When a visitor uses "Report sticker", we record the selected reason, report details (up to 500 characters), a pseudonymised HMAC digest of the IP address, the date and case status, and a snapshot of the sticker name, Owner message and phone numbers visible at the time of the report. We do not store the raw IP address.
The data is used to assess the report, protect users and the Service, prevent abuse, comply with legal duties and establish, exercise or defend claims. The legal basis is Art. 6(1)(f) GDPR and, where applicable, Art. 6(1)(c). Access is limited to authorised administrators; data may be disclosed to a competent authority where required by law. It is retained while the matter is reviewed and afterwards only for as long as necessary for those purposes and applicable limitation periods, then deleted or anonymised.
Each report is assessed individually, and the number of reports alone does not establish a violation. Report data and the preserved content snapshot may be used to make and document a moderation decision, including a decision to block a sticker permanently where a serious or repeated violation is confirmed.
4. Legal Basis and Purposes of Processing
| Purpose | Legal Basis (Art. 6 GDPR) |
|---|---|
| User account management | Art. 6(1)(b) β performance of a contract |
| Order fulfilment and payments | Art. 6(1)(b) β performance of a contract |
| Contact form (anonymous messages) | Art. 6(1)(b) β contract / Art. 6(1)(f) β legitimate interest |
| QR sticker delivery | Art. 6(1)(b) β performance of a contract |
| Web push notifications | Art. 6(1)(a) β consent |
| Email marketing | Art. 6(1)(a) β consent |
| Security and abuse prevention (rate limiting, CAPTCHA, spam detection) | Art. 6(1)(f) β legitimate interest in protecting the service and users |
| Tax and accounting obligations | Art. 6(1)(c) β legal obligation |
| Establishing or defending legal claims | Art. 6(1)(f) β legitimate interest |
| Anti-spam protection (browser fingerprint) | Art. 6(1)(f) β legitimate interest |
| GPS location sharing in Lost Mode | Art. 6(1)(a) GDPR β consent |
| Withdrawal and return process | Art. 6(1)(c) GDPR β legal obligation (Polish Consumer Rights Act) and Art. 6(1)(b) β performance of a contract |
5. Data Retention Periods
- User account:While the service is used; a deletion request has a 7-day cancellation period and remaining personal data is erased no later than 30 days after the request
- Transaction data:For the statutory tax and accounting period, generally 5 years from the end of the calendar year in which the tax payment deadline passed; this may be extended if the limitation period is suspended or interrupted
- Account deletion registry:A pseudonymous HMAC, process dates, sticker codes/statuses and retained order numbers β until the end of the sixth year after the request, solely to demonstrate compliance and defend legal claims
- Passkeys and security audit:credential until the Passkey or account is removed; pseudonymous add, replace and delete audit β up to 2 years
- Pseudonymous app-installation link:Up to 180 days from the last activity; removed earlier with the session or account
- Contact form messages:30 days from sending, unless the user deletes them earlier or longer retention is necessary to establish, pursue or defend legal claims
- Browser fingerprint signals attached to a message:30 days from message date (stored alongside the contact form message)
- Anti-spam blocklist (HMAC'd device signals):Up to 90 days from the date the block was created. Data is stored exclusively in pseudonymised form (HMAC digest β not raw browser data) and is used solely to protect sticker owners from unwanted messages.
- Scan fingerprint cookie:15 minutes (qrkontakt_fp; used only to suppress repeated scan push notifications)
- QR scan data:the scan counter and timestamp history are stored with the sticker until the sticker or account is deleted; short-lived scan rate-limit data is stored for up to 30 minutes
- Sessions and cookies:30 days (remember_me cookie), browser session (session cookie)
- Push tokens and device data:active token until logout, consent withdrawal, app removal or an invalid-token response from FCM/APNs; technical device-session record until account deletion, with the pseudonymous installation link removed after 180 days of inactivity
- Rate limiting logs:24 hours
6. Recipients and Data Transfers
Your data may be shared with the following third parties (only to the extent necessary to provide the service):
Stripe Inc.
Card payment processing. Certified payment processor. USA β transfers under Standard Contractual Clauses (SCC). Stripe Privacy Policy
mBank S.A. (PayNow)
BLIK and online bank transfer processing. Poland (domestic entity). PayNow Privacy Policy
Furgonetka.pl / Apaczka S.A. and postal or courier operators
Sticker delivery logistics. We share data necessary to create and handle shipment, in particular name, delivery address, phone number and shipment details. Relevant operators are generally established in Poland or the EU.
Brevo / transactional email provider
Delivery of system messages, confirmations, notifications and transactional correspondence. We share the email address, system message content and technical delivery metadata needed for sending and diagnostics.
Cloudflare Turnstile
Protection of forms against spam and automated abuse. Cloudflare receives the verification token, IP address and technical data required to verify whether the form is completed by a human.
Google LLC (Google OAuth)
Sign in with Google. USA β transfers under SCC. Google Privacy Policy
Apple Inc. (Sign in with Apple)
Sign in with Apple. USA β transfers under SCC. Apple Privacy Policy
Google Firebase Cloud Messaging and Apple Push Notification service
Mobile notification delivery. We send the device token, notification content, event-routing data and technical delivery parameters. Firebase may also process the Firebase Installation ID and SDK diagnostics; APNs processes the device token and delivery metadata.
Sentry (Functional Software, Inc.)
Application error monitoring (if configured). Technical diagnostic data is processed with data minimisation. USA β transfers under appropriate legal transfer mechanisms.
Discord Inc. / internal operational webhooks
Internal operational notifications about events such as sticker activation, paid orders or support tickets. The scope is limited to identifiers, order numbers, sticker codes, ticket categories and shortened descriptions necessary for operations.
Hosting Provider
Server infrastructure and database hosted within the European Union.
Where data is transferred outside the European Economic Area, we use required legal mechanisms, in particular Standard Contractual Clauses, adequacy decisions or other currently required safeguards.
The controller does not sell or share personal data with third parties for marketing purposes.
7. Message Moderation and Administrator Access
The QrKontakt platform administrator has technical access to the content of messages submitted through the contact form and to any attachments included with those messages. This access is strictly limited to the purposes set out below and is exercised exclusively through an authenticated administrator account (ROLE_ADMIN).
Scope and purpose
The administrator may review message content and attachments solely for the following purposes:
- moderation of unlawful content, threats, harassment or other abuses reported by users or detected by automated systems;
- investigation of abuse reports and maintaining platform safety;
- compliance with lawful requests from public authorities (Art. 6(1)(c) GDPR β legal obligation);
- establishment, exercise or defence of legal claims.
Legal basis
Processing for the above purposes is based on Art. 6(1)(f) GDPR β the legitimate interest of the controller in maintaining a safe platform and preventing misuse. A Legitimate Interest Assessment (LIA) has been carried out prior to implementing this policy. The results of the LIA are available on request at [email protected].
Safeguards
- Every administrator access to a message or attachment is recorded in an audit log (who, when, which message was accessed).
- Access is restricted to administrator accounts authenticated with a separate password (ROLE_ADMIN).
- Messages and attachments are automatically deleted 30 days after the date of submission, unless longer retention is necessary for an open legal case.
- Audit logs are reviewed periodically to ensure proportionality of access.
Right to object (Art. 21 GDPR)
The sender of a contact form message or the sticker owner may object to the processing of their data based on the controller's legitimate interest. The controller will assess the validity of the objection and respond within the statutory period. Objections may be submitted in writing to: [email protected].
Notice to message senders: Messages sent through the contact form are delivered to the QR sticker owner. The platform administrator also has technical access to their content for moderation and platform safety purposes, as described in this section.
8. Your Rights
Under GDPR, you have the following rights:
Right of access (Art. 15)
You can find out what data we process about you and receive a copy.
Right to rectification (Art. 16)
You can request correction of inaccurate or completion of incomplete data.
Right to erasure (Art. 17)
You can request deletion of your data when it is no longer needed or you withdraw consent. You may also delete your account directly in your profile settings.
Right to restriction (Art. 18)
You can request that processing of your data be suspended in certain circumstances.
Right to portability (Art. 20)
You can receive your data in a structured, machine-readable format (CSV/JSON).
Right to object (Art. 21)
You can object to processing based on legitimate interest.
Right to withdraw consent
You can withdraw consent at any time without affecting the lawfulness of prior processing.
Right to lodge a complaint
You can lodge a complaint with the Polish supervisory authority (UODO), ul. Stawki 2, 00-193 Warsaw, uodo.gov.pl.
To exercise any of these rights, contact us at: [email protected]. We will respond without undue delay and no later than 30 days.
How to delete your account (Art. 17 GDPR)
You have the right to delete your account and associated personal data at any time. You can do this yourself in your profile settings or by writing to [email protected].
Upon deletion request:
- The account remains active for 7 days, and the request can be cancelled on the website or in the mobile app.
- After 7 days, login is blocked, sessions and push tokens are revoked, subscriptions are cancelled and QR stickers are deactivated.
- Remaining personal data is permanently erased no later than 30 days after the request.
- Anonymised order and invoice data remains for the statutory tax/accounting period, which may be extended when a limitation period is suspended or interrupted.
- We retain a limited pseudonymous process record (no name, email, contact details or message contents), including deactivated sticker codes and retained order numbers.
10. Security Measures
We apply the following technical and organisational measures to protect your data:
- βEncrypted connection (HTTPS) for the entire service
- βPasswords stored exclusively in encrypted form (one-way cryptographic hash)
- βAuthorization tokens encrypted with strong cryptographic algorithms
- βIP addresses never stored in plain form β only pseudonymised hashes
- βData isolation in separate databases (cache, sessions, protective mechanisms)
- βHTTP security headers following industry best practices
- βCSRF protection on all forms
- βRate limiting to prevent brute-force attacks
- βPayment card data processed exclusively by certified payment processors
11. Contact
For data protection matters, please contact us at:
- E-mail: [email protected]
- Address: ADAKS MEDIA DANIEL DOBROWOLSKI, MΕciszΓ³w 112B, 59-800 LubaΕ, Poland
- Website: qrkontakt.com
12. Changes to This Policy
The controller reserves the right to update this Privacy Policy. We will notify you of significant changes by email or through a prominent notice on the service at least 14 days before they take effect.
The current version of the Privacy Policy is always available at qrkontakt.com/privacy.
Campaign participantsβ personal data
To handle a request, we process the shipping code, sticker sizes and colours, request status and dates, accepted terms version and optional email address (GDPR Article 6(1)(b)). Keyed hashes of technical device and connection identifiers protect the service and associate reservations with a session (Article 6(1)(f), legitimate interest in security). Email is used for request notifications, not marketing enrolment. Without a shipping code and sticker selection we cannot fulfil a request; email is optional, but without it there are no email notifications or correction links. Requests are reviewed by the organiser, not solely by automated decision-making.
Request data is retained while the request and related complaints are handled. Afterwards, only data necessary to establish, exercise or defend legal claims may be retained until the applicable limitation period expires, or data required by a specific legal obligation for the period that obligation requires. Shipping codes are also retained during the campaign to prevent assignment to multiple requests. Once these grounds cease, data should be deleted or anonymised. Recipients may include hosting, transactional email, operational notification and diagnostics providers described in the privacy policy. InPost independently processes shipment data entered in its app.
Under the GDPR you may request access, rectification, erasure, restriction and portability, and object to processing based on legitimate interests. You may also complain to the Polish data protection authority (President of UODO). Contact the organiser about your data. Details about providers and possible transfers outside the EEA are available in the privacy policy.